package cn.tedu;

import java.sql.*;
import java.util.Scanner;

public class Demo10 {
    public static void main(String[] args) {
        Scanner scan = new Scanner(System.in);
        System.out.println("请输入用户名:");
        String username = scan.nextLine();
        System.out.println("请输入密码:");
        String password = scan.nextLine();
        try (Connection connection = DBUtils.getConn()) {
//            Statement statement = connection.createStatement();
//            ResultSet rs = statement.executeQuery("select count(*) from user where username='"+username+"' and password='"+password+"'");
            String sql = "select count(*) from user where username=? and password=?";
            PreparedStatement ps = connection.prepareStatement(sql);
            ps.setString(1,username);
            ps.setString(2,password);
            ResultSet rs = ps.executeQuery();
            rs.next();
            int count = rs.getInt(1);
            System.out.println(count == 0 ? "登录错误" : "登录成功");


        } catch (SQLException throwables) {
            throwables.printStackTrace();
        }

    }
}
